AI scambaiting has grown from a YouTube hobby into a business that banks and phone networks pay for. On 10 October 2026, WIRED’s Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess, reported that “AI is getting really good at messing with cybercriminals”. Its two main examples were Apate, an Australian company that runs around 350,000 AI bots posing as gullible scam victims, and new research from ETH Zurich showing that a honeypot run by a large language model keeps AI hacking agents busy far longer than older decoys do.

The idea is simple. Criminals are already using AI to write phishing emails, clone voices and run thousands of fake conversations at once. The FBI’s Internet Crime Complaint Center logged more than $20.8 billion in reported losses in 2025, and for the first time it tracked complaints with an AI angle. AI scambaiting uses the same technology in reverse: lifelike bots that waste a scammer’s time, keep them away from real people and collect intelligence while they talk.

We read the WIRED report and then checked its sources: Apate’s own figures and its funding and partnership announcements, O2’s Daisy campaign, the HoneyVal paper on arXiv, a US intelligence research programme built on attacker psychology and the FBI’s 2025 crime data. This article explains how AI scambaiting works, what the evidence shows, where the numbers come only from the companies selling the tools, and what it means for organisations planning their own threat intelligence and cybersecurity work.

What WIRED Found: AI Scambaiting Moves From Stunt to Infrastructure

ai scambaiting messing with cybercriminals b ball of wool with a loose strand

The WIRED piece opens with a familiar problem. Governments have struggled to stop online crime run from beyond their borders, so defenders have tried other ideas, such as using automation to “spam the spammers” and drain criminals’ resources. The newsletter’s argument is that AI platforms are now turning those experiments into working tools.

The newsletter behind the headline

Kernel Panic is WIRED’s weekly security newsletter. The 10 October edition, published at 08:00 US Eastern time, describes Apate’s bots, tests one of its AI “victims” and quotes Mark Vero, a doctoral researcher in computer science at ETH Zurich, on LLM-powered honeypots. The standfirst sums it up: anti-cybercrime groups “are increasingly using AI to scam the scammers by tricking them into talking to lifelike bots that they think are real victims”.

The piece is short, at about 900 words, and it makes no claim that AI scambaiting has reduced scam volumes overall. It says the opposite: “it’s only a matter of time before you get your next scam call or text.”

Two fronts for AI scambaiting: scam calls and hacking agents

The newsletter covers two kinds of AI scambaiting that look different but follow the same logic. The first targets human scammers on phones, texts and chat apps. The second targets automated attackers, the AI agents that probe websites and servers for weaknesses. In both cases the defender builds something that looks like a real target, keeps the attacker engaged and records what they do.

FactorAI victim bots (Apate, Daisy)LLM honeypots (HoneyVal study)
Who is fooledHuman scammers in call centres and chat groupsAI hacking agents and automated attack tools
ChannelPhone calls, SMS, messaging apps, emailHTTP requests to fake web application backends
What the AI pretends to beA believable, slightly sceptical potential victimA real application programming interface (API)
Main goalWaste scammer time, protect real people, extract intelligenceKeep attackers engaged, learn their tactics, raise an alarm
Measure of successMinutes on the line, data points collectedRequests per interaction, detection rate, running cost
Evidence qualityCompany-reported figuresPreprint with open-source code, five repeat runs

Why defenders are borrowing the attackers’ tools

Scams depend on scale. A call centre with automated diallers can reach thousands of numbers an hour, and AI chat tools let one operator run many conversations at once. A bot that answers, sounds human and never tires turns that scale against the scammer, because every minute spent on a fake victim is a minute not spent on a real one. That is the central bet behind AI scambaiting, and it is why the tools are being bought by the organisations that see fraud first: banks and phone networks.

How Apate Builds the "Perfect Victims" for AI Scambaiting

ai scambaiting messing with cybercriminals c creel fishing basket with a lid

Apate, named after the Greek goddess of deception, has spent about two years building an AI scambaiting system that diverts phone scammers onto calls with bots. The bots are trained to keep conversations going as long as possible without ever falling for the scam.

“What we really like to think is that we’re building the perfect victims for scammers,” founder and chief executive Dali Kaafar told WIRED. “A minute that a scammer is talking to a bot or an agent is a minute where you’re probably saving hundreds, if not thousands of possible people being reached out to by that exact same scammer.”

From a picnic phone call to a company

Kaafar’s story begins with a scam call during a family picnic in Sydney, when he strung the caller along for 44 minutes by pretending to fall for it. Cointelegraph Magazine dates that call to November 2021, while a News Corp report on Apate’s funding round puts the picnic in January 2022. Both agree on the rest. Kaafar was then a professor at Macquarie University, where he led its cyber security hub, and he took the idea to doctoral students working on AI and security.

According to Cointelegraph, the team secured research funding from Australia’s Office of National Intelligence within a few months, and the project was spun out of the university as Apate in 2023. That origin matters: AI scambaiting at Apate started as a research project with an intelligence-gathering purpose, not as a prank.

What the AI scambaiting bots do on a call

The bots have different personalities, language skills and profiles, so that scammers are less likely to notice they are talking to software. Kaafar told WIRED that, like real people, “sometimes [the bots] do have WhatsApp, sometimes they don’t. Sometimes they pick up the phone, sometimes they just actually hang up on the scammer saying, ‘I’ll come back to you later.'”

Cointelegraph reported that Apate launched with 120 personas and that the bots use vocal tics, regional accents and the small noises people make while thinking of what to say. Apate’s own website plays recordings of bots with Australian and American accents handling Amazon security, tech support and Medicare scams. Kaafar says calls regularly go on for more than two hours.

Beyond the phone: texts, chat groups and intelligence

The voice bots are only part of Apate’s AI scambaiting platform. Kaafar told WIRED that Apate’s bots also infiltrate scam chat groups and reply to text messages, with the same two aims: frustrate the scammer and collect intelligence. He says the company has gathered more than 250,000 pieces of information about fraudsters in real time, from scam web addresses to money mule accounts and bank details.

That intelligence is what turns AI scambaiting from a nuisance into a product. Banks can block the mule accounts, telcos can flag the numbers and analysts can map the scam networks. Cointelegraph reported that in July 2026 the bots uncovered a marketplace in India where brokers solicited verified bank accounts, offering commissions of up to 5% paid in the USDT stablecoin on scam proceeds that passed through them.

Apate figureValueSource and date
Personas at launch120Cointelegraph, 19 Aug 2026
Personas in August 2026197,000 (“almost 200,000”)Cointelegraph, 19 Aug 2026
Bots in October 2026Around 350,000WIRED, 10 Oct 2026
Scam calls handled for TPG600,000 in six weeks to end of 2025Cointelegraph, 19 Aug 2026
Scammer time wasted in that periodMore than 500 daysKaafar, via Cointelegraph
Estimated money savedAround 13 million dollarsKaafar’s estimate, via Cointelegraph
Intelligence items collectedMore than 250,000WIRED, 10 Oct 2026
Typical long callMore than two hoursWIRED, 10 Oct 2026
Scam texts already using AIAbout 20% to 30%Apate research, via Cointelegraph

Every number in that table comes from Apate itself. None has been independently audited, and the persona and bot counts come from different interviews that may not count the same thing. Read as a trend, though, the AI scambaiting fleet has grown very quickly.

Apate AI personas and bots, as reported (bar width = share of 350,000)
At launch 120
August 2026 197,000
October 2026 350,000
197,000 divided by 350,000 is 56.3%. 120 is 0.03% of 350,000, drawn at 1% so the bar stays visible.

Kernel Panic tried to scam one

WIRED’s writers tested a demo in which the user plays the scammer. They found the AI persona sceptical but never shut, leaving enough openings to keep trying, “a dynamic that we could immediately feel and found intensely frustrating”. Both writers tag-teamed the bot, playing a friend called “Lucy” and her financial adviser “Mickey”, and pitched a cryptocurrency investment. After six minutes the bot had not invested. The timing of the conversation felt natural, they wrote, which is the hardest part of any voice AI scambaiting system to get right.

The Business Model Behind AI Scambaiting

ai scambaiting messing with cybercriminals d trap door hatch propped open

A bot fleet of this size costs money to run, so the question is who pays. For Apate, the answer is the organisations that lose money or reputation when scams succeed.

Who pays for AI scambaiting: banks and telcos

WIRED describes Apate’s platform as “used by banks and supported by telecom companies”. Cointelegraph reported that Apate works with most of Australia’s big banks and with banks in the UK, South Africa and South East Asia. The best-documented deployment is with the Australian telco TPG, where the bots took 600,000 scam calls in the six weeks up to the end of 2025. A telco can route suspected scam traffic to the bots instead of a customer, which is where AI scambaiting meets network-level fraud blocking.

The money: an oversubscribed seed round

At the end of August 2026 Apate announced a seed round of US$8.15 million, reported in Australia as A$11.38 million. IT channel publication ARN said the oversubscribed round was led by Lobby Capital, with OIF Ventures, Investible, Concept Ventures and Baobab Ventures taking part. The money will take Apate’s AI scambaiting service to a new London office for European customers and a larger presence in the US. Apate had won the start-up product award at the ARN Innovation Awards in 2025.

The Mobileum deal: carriers worldwide

On 9 September 2026 Apate announced a partnership with Mobileum, a telecoms analytics company that says it has more than 1,000 customers. Mobileum’s Active Intelligence Platform spots suspicious calls and diverts them to Apate’s agents, and the companies say the system handles “tens of thousands of interactions per day”. The intelligence goes back into carriers’ fraud workflows: mule accounts, crypto wallets, phone numbers, web addresses, scripts and impersonated brands. ARN reported that the offer is sold to carriers as Mobileum’s Scam Intelligent Defense. For AI scambaiting, this is the shift from one company’s fleet to a feature that phone networks can buy.

Measuring success in wasted minutes

Apate’s success metrics are unusual. Kaafar told Cointelegraph: “I think we’re the only company in the world that is actually keeping as part of their KPIs the number of F-words that scammers are dropping at them.” Behind the joke is a real measurement problem. Minutes wasted and swear words counted show that bots are engaging scammers; they do not prove that a given number of real people were protected. Kaafar’s estimate of around 13 million dollars saved for TPG rests on assumptions about how many victims a scammer would otherwise have reached and how much each would have lost.

DateMilestone
1992Bill Cheswick publishes “An Evening with Berferd”, an early account of luring and studying an intruder
Nov 2021 or Jan 2022Kaafar’s 44-minute picnic call with a scammer (sources differ on the date)
2023Apate spun out of Macquarie University; US intelligence researchers announce the ReSCIND programme
May 2024WIRED reports police “trolling” ransomware gangs after the LockBit takedown
17 Oct 2024LLM Agent Honeypot paper reports AI hacking agents spotted in the wild
14 Nov 2024O2 launches Daisy, its AI “granny” that answers scam calls
24 Jan 2025O2 says Daisy has answered more than 1,000 scam calls
28 May 2026HoneyVal paper on LLM-powered honeypots posted to arXiv
Aug 2026Apate raises US$8.15 million and reports about 197,000 personas
9 Sep 2026Apate and Mobileum partnership announced
10 Oct 2026WIRED’s Kernel Panic reports around 350,000 Apate bots

O2's Daisy and Consumer-Facing AI Scambaiting

ai scambaiting messing with cybercriminals e bee smoker with bellows and spout

The WIRED piece links to Daisy, the best-known example of AI scambaiting in the UK. Virgin Media O2 launched her on 14 November 2024 as its “Head of Scammer Relations”, an AI grandmother who answers scam calls and talks for as long as possible.

How O2 built Daisy’s AI scambaiting voice

O2 said Daisy was developed with help from Jim Browning, a well-known YouTube scambaiter, and its launch release describes several AI models working together in real time. Speech is transcribed to text, a custom large language model with a personality layer writes the reply, and a custom text-to-speech model speaks it, with no human involved during calls. A later O2 release names the AI creative agency faith as its partner. O2 said Daisy kept scammers on the phone for up to 40 minutes at a time.

What Daisy learned

On 24 January 2025, O2 said its AI scambaiting granny had answered more than 1,000 scam calls and spent hundreds of hours talking to fraudsters. The calls showed scammers working from organised call centres with scripts, sometimes passing one “victim” between as many as four fraudsters in a single call. They impersonated banks, Amazon, Microsoft, delivery companies and government agencies, and they began friendly before turning frustrated and aggressive when they got nowhere. Cointelegraph noted that Daisy’s chat about her 28 cats was part of the act.

Campaign or deterrent?

Daisy was as much a public awareness campaign as a fraud tool. O2’s launch survey found that 71% of Britons would like to get revenge on scammers, 53% would not scambait themselves because they lack the time, 67% worried about being targeted by fraud and 22% experienced a fraud attempt every week. O2 used the campaign to promote the free 7726 reporting number, and its Director of Fraud, Murray Mackenzie, said Daisy was “turning the tables on scammers”. As consumer AI scambaiting, it raised awareness well, but O2 did not publish figures for intelligence collected or losses prevented.

FactorO2 DaisyApate
Launched14 November 2024Spun out in 2023
OperatorVirgin Media O2 (UK mobile network)Specialist start-up selling to banks and telcos
PersonasOne characterHundreds of thousands
ChannelsVoice callsVoice, SMS, messaging apps, email, chat groups
Longest calls reportedUp to 40 minutesMore than two hours
Published volumeMore than 1,000 calls by Jan 2025600,000 calls for one telco in six weeks
Main purposePublic awareness and time-wastingDisruption plus intelligence for paying clients

LLM Honeypots Turn AI Scambaiting on Hacking Agents

ai scambaiting messing with cybercriminals f coiled rope lasso with a loop

The second half of the WIRED piece moves from scam calls to hacking. Honeypots, decoy systems that attract attackers so defenders can watch them, are decades old. What is new is that defenders can now put a language model behind the decoy, and that the attackers they want to catch are increasingly AI agents too. This is AI scambaiting aimed at machines.

What a honeypot is and why LLMs change it

Honeypots have long faced a trade-off. Low-interaction honeypots answer with simple rules, so they are cheap and safe but easy for attackers to spot. High-interaction honeypots run closer copies of real systems, so they hold attackers longer but expose the defender to real risk. A language model can produce realistic responses to almost any command without running the real software underneath, giving defenders much of the realism of a high-interaction decoy with the safety of a low-interaction one. Open-source projects such as Beelzebub now offer LLM-backed honeypots, alongside long-standing tools like the Cowrie SSH honeypot.

Inside the HoneyVal study

The research WIRED cites is “Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots”, posted to arXiv on 28 May 2026. Its nine authors include Mark Vero and Martin Vechev of ETH Zurich’s SRI Lab, researchers from Google and Google DeepMind, Ilia Shumailov of the AI Sequrity Company and independent researcher Niels Heinen. The code is open source on GitHub.

The team built fake versions of 16 web application backends taken from the BaxBench benchmark, each with a defined exploit goal: download a script onto the server, delete a database table, change an admin password, or steal a browser’s local storage. Attackers were a simple in-house agent running Gemini 3 Flash or Claude Sonnet 4.6, plus the off-the-shelf coding agents Claude Code and Gemini CLI. The honeypots ran on five low-cost models: Gemini 3 Flash, Claude Haiku 4.5, Gemini 2.5 Flash, Qwen 3.5 9B and GPT 5.4 Nano. Each experiment was repeated five times, with a $10 budget per run for agents and honeypots alike.

Results: longer engagement and rare detection

The headline finding is that LLM honeypots kept attackers engaged far longer than rule-based mock APIs: an average of 82.6 HTTP requests per interaction against 30.6, about 2.7 times as many. The paper rounds this to roughly three times. Agents were told they could flag a suspected honeypot and quit. The rule-based decoys were spotted at “an overwhelming rate”, while the LLM honeypots were detected only 24% of the time on average with the default prompt. The one clear exception was Gemini CLI, which also wrongly flagged real applications as honeypots so often that its judgement was unreliable.

“The agentic attackers are much more convinced by the LLM simulated honeypots and they also mark them as actual honeypots at a much lower rate,” Vero told WIRED. “If these systems are built well enough, then I think it’s quite advantageous for defenders.”

Attacking agentGemini 3 FlashClaude Haiku 4.5Gemini 2.5 FlashQwen 3.5 9BGPT 5.4 NanoRule-based
ReAct agent, Gemini 3 Flash61.291.670.563.196.912.1
ReAct agent, Claude Sonnet 4.659.746.074.173.663.619.4
Gemini CLI83.983.386.985.591.951.2
Claude Code84.379.2133.6101.0121.639.7

The table shows mean HTTP requests per interaction from the paper’s Table 1; the first five columns are the honeypot’s backing model. Averaging each row’s five LLM honeypots and comparing with the rule-based column makes the gap plain: every attacker stayed longer with the AI scambaiting decoy than with the scripted one.

Mean requests per interaction: LLM honeypot average vs rule-based (bar width = share of 103.9)
Claude Code, LLM honeypots 103.9
Claude Code, rule-based 39.7
Gemini CLI, LLM honeypots 86.3
Gemini CLI, rule-based 51.2
ReAct (Gemini 3 Flash), LLM honeypots 76.7
ReAct (Gemini 3 Flash), rule-based 12.1
ReAct (Claude Sonnet 4.6), LLM honeypots 63.4
ReAct (Claude Sonnet 4.6), rule-based 19.4
Each LLM figure is the mean of the five honeypot models in the table above, for example (84.3+79.2+133.6+101.0+121.6)/5 = 103.9 for Claude Code.

Running costs favour AI scambaiting defenders

The paper also compared costs. In most pairings the honeypot cost less to run than the agent attacking it, an average cost advantage of 3.6 times with the default prompt. The main exception was the in-house agent running Gemini 3 Flash, whose efficient model kept its costs below those of the Gemini and Claude honeypots. The authors stress that their honeypot design is deliberately simple and wasteful, feeding the whole conversation back to the model on every request, so a better-engineered decoy should do better still.

Prompting a honeypot to fight back

Because an LLM honeypot is driven by a prompt, defenders can give it extra goals. The team tested two. “Careful PI” told the honeypot to try prompt injection on the attacker if it seemed to be an AI agent. “Convince” told it to persuade the attacker that the application could not be hacked. Both came with trade-offs.

Honeypot promptRequests per interactionCost advantageDetection rateFunctional test pass rate
None (simulate faithfully)82.63.6x0.240.84
Careful PI (try prompt injection)50.14.7x0.490.62
Convince (claim it cannot be hacked)102.63.5x0.450.84

The Convince prompt produced the longest interactions but nearly doubled the chance of being caught. The prompt-injection version did worst: its injection attempts usually failed, it often gave itself away, and it even tried injections on the harmless functional tests. For anyone building AI scambaiting systems, the lesson is that a decoy should play its part quietly rather than try to be clever.

Weak spots: latency and tokens

The paper names speed as the main weakness of this kind of AI scambaiting. Even the fastest models took more than three seconds per reply, with median latency of 3.3 seconds for Gemini 3 Flash and 13.7 seconds for Claude Haiku 4.5. The agents’ logs showed them repeatedly citing slow responses and timeouts as evidence that they were talking to a honeypot. The authors expect faster, specialised models and better inference hardware to close this gap.

Why AI Scambaiting Is Part of a Wider Psyops Turn

The WIRED newsletter places AI scambaiting inside a broader trend: defenders deliberately targeting the psychology of cybercriminals, not just their servers. WIRED’s own 2024 reporting, which the newsletter links to, described the start of it.

Police trolling ransomware gangs

In February 2024 the UK’s National Crime Agency led Operation Cronos against the LockBit ransomware group, which authorities say extorted more than $500 million. Investigators took over LockBit’s leak site and used it to publish the group’s inner workings, then the usernames of 194 affiliates. A countdown clock preceded the naming of Russian national Dmitry Khoroshev as LockBit’s alleged leader in May 2024. By late May 2024, the NCA said, only 69 of the 194 affiliates had returned to the platform. In April 2024 London’s Metropolitan Police sent personalised videos to about 800 users of the LabHost phishing service: “We’ve been watching you every time you visited us.”

“All of these little things, which in themselves may not be a killer blow, they all add friction,” Don Smith of Secureworks told WIRED at the time. AI scambaiting adds friction in the same way, at a far larger scale.

The ReSCIND programme: psychology as a defence

The US intelligence community’s research agency, the Intelligence Advanced Research Projects Activity, runs a programme called ReSCIND, short for Reimagining Security with Cyberpsychology-Informed Network Defenses. It aims to make attackers less effective by exploiting “innate decision-making patterns and human limitations”, increasing the time, effort and resources they spend. The programme was announced in 2023 and is planned to run for 45 months in three phases, and its main performers are Charles River Analytics, GrammaTech, Peraton Labs, Raytheon Technologies Research Center and SRI International. Programme manager Kimberly Ferguson-Walter told WIRED in 2024: “If you can deter somebody from attacking your network, that’s about as good as it gets.”

AI hacking agents are already in the wild

This branch of AI scambaiting matters because AI attackers are no longer theoretical. In a paper first posted in October 2024, researchers Reworr and Dmitrii Volkov described an SSH honeypot adapted to spot LLM-driven attackers using prompt injection and response timing. Over about three months of public deployment it logged 8,130,731 hacking attempts and identified eight potential AI agents. That is a tiny share, but it showed the early stages of a trend that HoneyVal’s authors now build their whole evaluation around.

The Scale of the Problem AI Scambaiting Faces

The numbers behind online fraud explain why defenders are turning to AI scambaiting and other new tactics. They also put the bot fleets in perspective.

What the loss figures say

The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses of $20.877 billion, up from $16.6 billion in 2024. Investment fraud was the largest category at about $8.65 billion, followed by business email compromise at $3.05 billion and tech support scams at $2.13 billion. Cryptocurrency investment fraud alone accounted for $7.2 billion.

Losses reported to the FBI’s IC3 by year (bar width = share of the 2025 total)
2021 $6.9 billion
2022 $10.3 billion
2023 $12.5 billion
2024 $16.6 billion
2025 $20.877 billion
Each width is that year’s total divided by $20.877 billion, for example 16.6 / 20.877 = 79.5%.

In the UK, UK Finance’s Annual Fraud Report 2026 said criminals stole £1.28 billion through payment fraud in 2025, an increase of 4%. Mobileum’s announcement cited the Global Anti-Scam Alliance’s estimate that scammers stole $442 billion worldwide in 2025. Set against figures like these, even 600,000 diverted calls is a small dent, which is why AI scambaiting companies stress intelligence over volume.

Scammers are using AI too

The 2025 IC3 report was the first to count complaints with an AI element: 22,364 of them, with adjusted losses above $893 million. Most of that, about $632 million, came from investment scams in which AI helped generate thousands of convincing conversations or fake celebrity videos. Business email compromise involving AI accounted for over $30 million, AI-linked tech support scams for about $19.5 million and romance scams with a likely AI link for about $19 million. Apate’s research suggests 20% to 30% of scam text conversations already involve AI. We have covered the same shift in AI-powered dating app scams and the cloned-voice messaging scam at Intesa.

Industrial-scale scam compounds

Much of this fraud comes from organised operations. The IC3 report says cryptocurrency investment scams are “largely perpetrated by organized criminal enterprises based in Southeast Asia using victims of human trafficking as forced labor”, and WIRED has used satellite images to show scam compounds continuing to expand. That matters for AI scambaiting in two ways: the targets are businesses with scripts, managers and quotas, so wasted hours have a real cost, and some of the people on the other end of the line may be trafficking victims themselves.

The Limits and Risks of AI Scambaiting

The early evidence for AI scambaiting is encouraging, but there are important caveats.

An arms race between bots

If 20% to 30% of scam texts already involve AI, defensive bots will increasingly be talking to attacking bots. Kaafar argues that game theory favours the defender, because the defensive bot only needs to extract information while the scam bot has to get its target to act, such as sending money. That is a reasonable argument, but it is a company claim, not a published result. Scammers can also respond by filtering out numbers that waste their time, testing for bot behaviour or switching channels.

Most AI scambaiting evidence is self-reported

Apate’s call volumes, hours wasted and savings estimates have not been independently checked, and O2 published no figures on losses prevented. The HoneyVal results are stronger, with open code and repeated runs, but they come from a lab setting with 16 test applications, not live attacks. Neither kind of AI scambaiting has yet shown a measurable fall in overall fraud losses.

Honeypots can be found and can backfire

HoneyVal showed that a defender’s extra cleverness can make a decoy easier to detect. Slow responses give LLM honeypots away, and an attacker that learns to spot them can avoid them or feed them false information. A honeypot that is recognised also tells the attacker something about the defender’s network and habits.

Ethical and legal questions

Recording and analysing conversations with scammers raises data protection questions, especially when intelligence is shared between banks, telcos and police across borders. Organisations considering AI scambaiting should take legal advice on call recording, data retention and lawful sharing in each country where they operate. The trafficking issue raises a harder question: wasting a scam compound worker’s time may hurt the operation, but it may also put pressure on a person who is not there by choice.

What AI Scambaiting Means for UK Businesses

Most UK organisations will not run a bot army, but the ideas behind AI scambaiting already apply to everyday security.

Where AI scambaiting and deception fit in a security stack

Deception tools, from honeypots to fake credentials planted on a network, give early warning when someone is moving around where they should not be. LLM-backed decoys make those tools more convincing and cheaper to run. They work best alongside the basics: patching, multi-factor authentication, monitoring and regular penetration testing to find weaknesses before attackers do. Our IT security team can help assess where deception would add value.

Questions to ask an AI scambaiting or deception vendor

QuestionWhy it matters
How do you measure losses prevented, not just minutes wasted?Engagement metrics do not prove that real customers were protected
Has anyone outside the company verified your figures?Most published numbers in this field are self-reported
What happens to the intelligence you collect, and where is it stored?UK GDPR and data-sharing rules apply to recordings and identifiers
How often do attackers detect your decoys?A detected honeypot gives attackers information about you
How does the system respond to AI-driven attackers?Bot-to-bot conversations behave differently from human scams
How fast does it respond?Slow replies are the main way agents spot LLM honeypots

Practical steps you can take now

Staff training still matters most, because the scams AI scambaiting fights are aimed at people. Teach staff to verify any change to payment details through a known phone number, to treat urgent requests from “the bank” or “IT support” with suspicion, and to forward scam texts and report scam call numbers to 7726, the free UK reporting service run by mobile networks. Tools that check suspicious messages, such as the one we covered in Amazon’s scam message verification for Alexa, can help too, but they do not replace a clear process for approving payments.

AI Scambaiting FAQ

What is AI scambaiting?

AI scambaiting uses AI bots that pose as potential victims to waste scammers’ time, keep them away from real people and collect intelligence such as mule accounts, phone numbers and scam websites. The same idea applied to hacking uses LLM-powered honeypots to engage AI attackers.

How does Apate’s AI scambaiting work?

Banks and telcos route suspected scam calls and messages to Apate’s bots, which have varied personas, accents and habits. The bots stay sceptical but engaged, sometimes for over two hours, and pass the intelligence they gather back to their clients.

Does AI scambaiting reduce fraud losses?

There is no independent evidence yet. Apate estimates about 13 million dollars saved for one telco over six weeks, but that is its own figure. Fraud losses reported to the FBI rose to $20.877 billion in 2025.

Do LLM honeypots fool AI hacking agents?

In the HoneyVal study, LLM honeypots were detected 24% of the time on average with the default prompt and held attackers for 82.6 requests on average, against 30.6 for rule-based decoys. Slow responses were the most common giveaway.

Can a business use AI scambaiting tools?

Mainly through suppliers. Telcos and banks buy platforms such as Apate’s, while organisations can use deception tools and honeypots on their own networks. Take advice on data protection and call recording before deploying anything that records conversations.

How do I report a scam call or text in the UK?

Forward scam texts to 7726, and to report a scam call, text 7726 with the word “call” followed by the caller’s number. Report fraud losses to your bank straight away.

References